7 ms·
I'd love if Firefox's built-in Tracking Protection did without an addon the job ClearURLs does, so two months ago I created Bug 1697982: "Firefox Tracking Prot
by ronjouch 5y ago
I'd love if Firefox's built-in Tracking Protection did without an addon the job ClearURLs does, so two months ago I created
Bug 1697982: "Firefox Tracking Protection should protect against URL/queryparam-based tracking (like ClearURLs/NeatURL addons do)" , https://bugzilla.mozilla.org/show_bug.cgi?id=1697982 https://bugzilla.mozilla.org/show_bug.cgi?id=1697982
Please vote for the bug if you'd like it too.
Also, I see a few interesting comments in this HN thread; this evening when the dust settles, I'll aggregate & bring them to the bug for consideration if/when fixing this bug is considered.
- eythian 5y agoI don't really know how I feel about having the browser mess with URLs without the user engaging it deliberately. It feels to me something that should perhaps be approached with caution. On the other hand, it does make sense. It's a tricky one.
- ChefboyOG 5y agoI think an automatic alert (which can be set to ignore by the user) which flags such links, and offers the option to turn on a config flag which enables URL manipulation like this, would be a good compromise.
- bonestamp2 5y agoYes, maybe some flag that comes up at the end of the address bar to indicate that it sanitized your URL. Then you can click the flag to see details about what it changed and have the option to navigate to the original URL.
- tinyhitman 5y agoMaybe prompt the user with a "use clean" or "use as-is" button (and "cancel"). and maybe a custom option; where you can toggle what is cleaned and whatnot. and provide a "remember for this domain".
- rakoo 5y agoFirefox already positioned itself when it gave the user a possibility to block tracking cookies and fingerprinting techniques. It's engaged even further now with Site Isolation. If utm_* query arguments are used solely for tracking, then it only makes sense that Firefox goes the next step
- sodality2 5y agoIt's possible it can be used for other things however, so it's a slippery slope. I block them anyway but maybe not default?
- IgorPartola 5y agoConversely, if you know that using utm_ parameters will break for a large number of your users, you just won’t use it, no?
- michaelmior 5y agoThis is a fair point. At this point, it's unlikely to break anything. But if it became the default, then any sites that do use them for something important would likely stop. Although there's nothing preventing sites from just renaming these parameters and modifying tracking code to keep tracking anyway.
- rakoo 5y agoIt's still used only for tracking only, so I'd say it's the right time to block them by default before they start being used for something else.
- michaelmior 5y agoI've seen some sites that use those parameters to activate specific features on a landing page for example. Pretty rare, but it does happen.
- freeAgent 5y ago
- darkwater 5y agoWell that's exactly the kind of job that an (opinionated) User Agent should do for you. <aybe configurable, maybe not. You can always change your agent (so, browser) if you don't like its opinion.
- arsome 5y agoI'm not so sure, by this logic we should have ad blocking by default as well, however that's a recipe for getting your browser banned by popular sites.
- kroltan 5y agoPopup blocking is basically standard and expected, don't see why ad blocking couldn't become so too.
- zo1 5y agoPopup blocking is definitely not standard and expected. There is a 90% chance of every website you visit to show a popup and not be "blocked" by the most privacy-conscious browsers. But. They're technically not "popups", they're just divs overlaying over the content that you were served but can't see. Or they're little slide-banners that nag you about signing up for a newsletter email or agreeing to tracking cookie non-sense. Oh and let's not forget about the popups asking you to allow "notifications" from this site, or to allow "location info" to be shared.
- matheusmoreira 5y ago> that's a recipe for getting your browser banned by popular sites Good luck with that. They have no choice but to believe whatever data the browser sends them, data that we control. If their precious content leaves their server at all they've already lost.
- Nextgrid 5y agoAd blocking by default is absolutely the way to go. Spoof the Chrome user agent if this actually becomes a problem (which would help with fingerprinting anyway). This is a bit like antivirus software authors worrying about being "banned" by the virus creators.
- matheusmoreira 5y agoIt's exactly the kind of thing user agents should do. If it's good for the user, they should do it by default for everyone.
- smithza 5y agoIt is at best neutral for the user. Sometimes these source trackers help companies know that affiliate links are more often drivers of traffic. Other times it helps with A/B testing because they discover the main logo was more often clicked than the "click me" button or whatever.
- leipert 5y agoBut how does this help me as a user? Affiliate links are often hidden, and depending on the system might even lead to higher prices, because the shop is offsetting the affiliate program cost. Whether the company does A/B testing, what does that have to do with me? That also can be implemented without external trackers and just be set in a session. So I would say it’s a net-positive.
- calvano915 5y agoCash back portals often require click through on affiliate links.
- ______- 5y ago> On the other hand, it does make sense. It's a tricky one. All attempts by Mozilla to bake-in addon-like behavior so we don't have to install 'yet another damn addon' is welcoming, but as with any of these features, they come with caveats already present in the addons. For example, Firefox's HTTPS-Only mode (that is basically the HTTPS-Everywhere addon) breaks some sites, and also their anti-tracking feature will break some sites too. But then again: if a site is serving HTTP only then they're doing it wrong (with the exception of captive portals). As for the anti-tracking feature: I rarely see sites asking me to disable my AD-Blocker, and when I do I never give-in, no matter how desperate I am to see hidden content.
- woko 5y agoExactly. Every time I have used an add-on like ClearURLs, I have had issues at some point due to some zealous clean-up of URLs which breaks a redirection. Typically, I don't want the browser to mess with my browsing if I am on the websites of my bank, a shop, etc.
- VortexDream 5y agoI think the problem with this is that ClearURLs can break legitimate uses for URL params. I need to disable it when I do things like online payment. That's not intuitive for users and means an integrated solution needs to take laypersons into account who wouldn't know how to solve the problem (or even what the actual problem is). Is that realistically solvable?
- ronjouch 5y agoThis is realistically solvable. 1. First, by Mozilla analysts & developers making a good job at rolling out a potential implementation in a safe progressive way, with the easiest stuff first (`fbclid`, `gclid`, etc), and then going deeper / per-site, maybe re-using (part of) existing filterlists. 1.1. Also, note that ClearURLs is quite aggressive (as noted by a few commenters, and I confirm): it strips lots of non-URLbar requests, strips ETags, etc. A sibling comment mentions that alternative NeatURL is less aggressive. As with all cat-and-mouse games, this is a trade-off, and an implementation in core Firefox doesn't have to go as far as ClearURLs, at least initially. Offering a strictness knob to users is also an option. 2. Then, Firefox already has UI to disable Tracking Protection and work around sites broken by it: click the shield at the left of your URL bar, then toggle off "Enhanced Tracking Protection is ON for this site" to see if it was ETP that broke the site. This UI maybe need adjustments / more granularity (and maybe not), sure.
- indymike 5y agoYou do realize that parameter names are easy to change?
- surround 5y agoMozilla themselves is guilty of link tracking. Any external link on addons.mozilla.org looks like this: outgoing.prod.mozaws.net/v1/25c02fd4e609951729e0ec0b41fe5391d912511b45d2a02aeaa839872c8d9def/https%3A//gitlab.com/KevinRoebert/ClearUrls
- wackget 5y agoYou should also suggest they remove their own garbage redirect tracking from the Firefox Addons site. Any URLs in the addon description section are all tracked/redirected via `https://outgoing.prod.mozaws.net https://outgoing.prod.mozaws.net`
- daveoc64 5y agoI am not a fan of making such functionality part of the browser. I use the HTTPS only mode in Firefox - it breaks some sites, and telling Firefox to disable the mode for a specific site doesn't always work. I feel like a plugin (HTTPS Everywhere) can deal with this a lot better than something that's integrated and reduced to a single checkbox in the settings.
- ronjouch 5y agoAnd I am a fan of making such functionality part of the browser :P : one less addon to manage & trust! Aside: the amount of insecure code in addons is scary, see https://palant.info/categories/security/ https://palant.info/categories/security/ , not to mention that addons are also a frequent cause of performance trouble (source: me, experienced several times). Thus, the more dubious addon code I'm able to replace with somewhat-well-maintained-and-audited Firefox code with many eyeballs on it, the better. (At this point, you or a passerby will point at the Pocket fiasco and argue that there's too much stuff shoved into our browsers and just stahp it already. Fair, and I love lean software too. I'd still like this specific feature because A. it's not Pocket, B. it aligns well with what Firefox is doing these days, and C. it aligns with what I expect from my user agent of choice). Then, supposing this ever makes its way into Fx, you can choose not to use it. And by the way, maybe like you, I will make the same choice if the Fx feature is too basic! But it will remain a win, for the users for whom it's good enough and who would never have bothered with an addon in the first place. Just like ETP vs. uBlock / PrivacyBadger / etc: ETP is a good basic "80%/20%" risk-less step in the right direction, and addons remains way ahead if you the user decide to bother a bit more. > "telling Firefox to disable [HTTPS only] mode for a specific site doesn't always work." This looks like a bug that you should report.
- guilhas 5y agoFirefox should worry about implementing standards as fast as possible and improve the browser speed And Stop trying to "re-implement" features for which there are already user extensions way more capable
- ronjouch 5y agoI understand the sentiment, but disagree with it in the case we're talking about, for reasons just as factual and pragmatic as yours. See my reply at https://news.ycombinator.com/item?id=27056751 https://news.ycombinator.com/item?id=27056751
- nagarjun 5y agoInstead of it being a default feature, I wonder if this makes more sense as a default in Incognito/Private browsing mode?